AramisAramis is an interactive tool to display, explore and understand network trafﬁc focusing on anomaly detection.
It displays trafﬁc at different temporal and spatial (address and port) scales and let the user navigate in network data. Different graphical representations are used to highlight anomalies, and textual information about plotted points are provided. For daily operations the tool reads directly pcap ﬁles and use no intermediate database.
Basic FeaturesIt can display network trafﬁc at different resolutions, and allow one to zoom in/out along time axis oraddress/port space. The tool provides different types of scatter plot corresponding to IP addresses or port numbers. The tool also provides time series like throughput and averagepacket size. All these graphical representations are easily understandable because they are limited to two dimensions. In order to characterize or to understand anomalies found in one of these graphical representations the tool allows one to compare two ﬁgures simultaneously. Analysing trafﬁc behaviour network operators have to focus on particular regions. The tool allows us to explore network trafﬁc easily. For daily use this tool can run on different platforms and it uses no intermediate database, it reads directly pcap ﬁles.
Use Patent Claims
Include Install Instructions
These details are provided for information only. No information here is legal advice and should not be used as such.